USN-7248-1: libndp vulnerability
It was discovered that libndp incorrectly handled certain malformed IPv6 router advertisement packets. A local attacker could possibly use this issue to cause NetworkManager to crash, resulting in a denial of service, or the execution of arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-7248-1?
The severity of USN-7248-1 is likely high due to the potential for denial of service and arbitrary code execution.
How do I fix USN-7248-1?
To fix USN-7248-1, you should upgrade to the patched version of libndp0: 1.6-1ubuntu0.1~esm1 for Ubuntu 18.04 or 1.4-2ubuntu0.16.04.1+esm1 for Ubuntu 16.04.
What versions of Ubuntu are affected by USN-7248-1?
Ubuntu versions 18.04 and 16.04 are affected by USN-7248-1.
What is the impact of the vulnerability described in USN-7248-1?
The impact of the vulnerability described in USN-7248-1 includes the potential crashing of NetworkManager and execution of arbitrary code.
Who can exploit the vulnerability in USN-7248-1?
A local attacker can exploit the vulnerability in USN-7248-1 by sending malformed IPv6 router advertisement packets.